Purpose
This Acceptable Use Policy forms part of the Cenrus Terms of Service and any customer agreement that refers to it. It protects patients, customers, payers, providers, and the security and reliability of Cenrus.
Use Cenrus only with authority
You may access or submit a person's bills, claims, Explanations of Benefits, payment evidence, insurance information, or other case data only when you have valid permission and a lawful business purpose. You must obtain and document patient authorization for payer connections. Do not ask a patient to give you or Cenrus a payer password.
Prohibited conduct
You may not:
- violate a law, contract, payer rule, provider right, or another person's rights
- access, retrieve, upload, change, or disclose records without valid authority
- impersonate a patient or other person or misrepresent your identity, purpose, or authority
- collect, store, or use a patient's payer login credentials
- use patient information for advertising, data brokerage, or an unrelated commercial purpose
- make unlawful credit, employment, insurance, eligibility, or discriminatory decisions
- present Cenrus results as proof of a provider's current balance or as a final coverage or payment decision
- remove evidence, confidence, or human-review notices from a result in a misleading way
- submit malware, unlawful content, deceptive requests, spam, or abusive traffic
- probe, scan, scrape, overload, disrupt, or bypass controls on the Service
- reverse engineer or copy the Service except where law bars this restriction
- use Cenrus or its outputs to build or train a competing product without written permission
- help another person do any of the acts listed above.
Customer controls
Customers must limit access to trained users who need it, review access when roles change, protect account credentials and integration keys, and remove access promptly when it is no longer needed. Customers must send uncertain or disputed cases to qualified people for review and maintain any records that law or their own obligations require.
Security and reporting
Promptly report suspected unauthorized access, data exposure, credential compromise, or a security vulnerability to security@cenrus.com. Do not publicly disclose a vulnerability before giving us a reasonable time to investigate and address it. Do not test with real patient information unless Cenrus has approved the test in writing.
Enforcement
We can limit, suspend, or terminate access when we reasonably believe conduct violates this policy or creates a legal, privacy, security, or operational risk. We can preserve evidence, contact the affected customer, and report conduct to a lawful authority when appropriate. Our response will reflect the nature and severity of the issue.